VYPR

Vendor CVEs

Fiberhome

All CVEs

64 total · sorted by risk
  • CVE-2021-27140HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.19

    An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.

  • CVE-2021-27139HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.16

    An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to extract information from the device without authentication by disabling JavaScript and visiting /info.asp.

  • CVE-2019-17187HigOct 8, 2019
    risk 0.50cvss 7.5epss 0.11

    /var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.

  • CVE-2022-36200HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.02

    In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.

  • CVE-2017-5544MedJan 23, 2017
    risk 0.39cvss 5.9epss 0.05

    An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's SSH service, using a password cracking tool to establish SSH connections quickly. This will trigger an increase in the SSH login timeout (each of the login…

  • CVE-2019-9556MedDec 31, 2019
    risk 0.38cvss 5.4epss 0.01

    FiberHome an5506-04-f RP2669 devices have XSS.

  • CVE-2022-38814MedSep 15, 2022
    risk 0.35cvss 5.4epss 0.03

    A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the sncfg_loid text field.

  • CVE-2021-41946MedMay 18, 2022
    risk 0.35cvss 5.4epss 0.02

    In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access Time Restriction --> Username field, a user cannot delete the rule due to the XSS.

  • CVE-2025-1616MedFeb 24, 2025
    risk 0.31cvss 4.7epss 0.08

    A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this issue is some unknown functionality of the component Diagnosis. The manipulation of the argument Destination Address leads to os command injection. The…

  • CVE-2024-51432MedNov 1, 2024
    risk 0.31cvss 4.8epss 0.00

    Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitrary code via the SSID field in the WIFI Clients List not being sanitized

  • CVE-2025-52357MedJul 9, 2025
    risk 0.27cvss 4.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firmware V2.2.14), allowing an authenticated attacker to execute arbitrary JavaScript code in the context of the router s web interface. The vulnerability is…

  • CVE-2025-1615LowFeb 24, 2025
    risk 0.16cvss 2.4epss 0.01

    A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerability is an unknown functionality of the component NAT Submenu. The manipulation of the argument Description leads to cross site scripting. The attack can be…

  • CVE-2025-1614LowFeb 24, 2025
    risk 0.16cvss 2.4epss 0.01

    A vulnerability classified as problematic has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected is an unknown function of the file /goform/portForwardingCfg of the component Port Forwarding Submenu. The manipulation of the argument pf_Description leads to cross site…

  • CVE-2025-1613LowFeb 24, 2025
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in FiberHome AN5506-01A ONU GPON RP2511. It has been rated as problematic. This issue affects some unknown processing of the file /goform/URL_filterCfg of the component URL Filtering Submenu. The manipulation of the argument url_IP leads to cross site…

Page 2 of 2